If you think Open Source Intelligence (OSINT) is just about Googling someone's name, you are doing it wrong. Real intelligence gathering is a disciplined tradecraft that requires a specific mindset, rigorous operational security (OpSec), and a toolkit that goes far beyond the surface web.
These OSINT Notes are the definitive companion, consolidating over 150 pages of search methodologies, command-line tools, and verification techniques into one lethal OSINT field notes collection.
Unlike generic people search tutorials that rely on expensive subscriptions, this guide focuses on the raw, technical methods used by professional analysts to track digital footprints, map infrastructure, and uncover the invisible.
Whether you are a journalist tracking a story, a Red Teamer performing reconnaissance, or a private investigator, this book provides the structured workflows you need to turn noise into actionable intelligence.
Master OpSec & Sock Puppets
The first rule of OSINT is do not get caught, and this guide takes that seriously. It doesn't just tell you to be careful; it gives you a blueprint for creating bulletproof sock puppet accounts.
You will learn why using a VPN during account creation often gets you flagged, and why burner phones (Mint Mobile) are superior to VoIP numbers for verification.
The notes detail the aging process for fake profiles on Facebook and LinkedIn to avoid algorithmic detection, ensuring your investigative persona survives long enough to get the data you need. This is the practical Open Source Intelligence Notes advice that separates the pros from the amateurs who get their accounts banned on day one.
Social Media Intelligence (SOCMINT) Deep Dive
Social media is a goldmine, but extracting data from it requires more than a web browser. These notes provide a command-line heavy approach to SOCMINT, featuring tools like Snscrape and Twint (Python-based scrapers) to bypass API limitations and download thousands of tweets or posts for offline analysis.
You will find specific workflows for Instagram and TikTok, including how to download stories anonymously, analyze follower/following relationships to map social circles, and even extract precise timestamps from TikTok video URLs to verify events. The guide also covers Telegram and Discord investigations, platforms often ignored by basic guides, teaching you to map group members and archive chat logs using tools like Telepathy and DiscordHistoryTracker.
Infrastructure, Domains, & The Dark Side
You cannot investigate a target without understanding their digital infrastructure. This guide serves as a technical OSINT field notes manual for mapping domains and networks. It covers advanced Shodan filters to find exposed webcams, open databases (MongoDB, Elasticsearch), and industrial control systems.
You’ll learn to use Maltego to visualize complex relationships between emails, domains, and IP addresses, turning scattered data points into a cohesive threat map. Furthermore, the notes dive into Blockchain OSINT, showing you how to trace Bitcoin and Ethereum transactions using block explorers to de-anonymize crypto wallets and link them to real-world entities.
People Search & Breach Data
When Googling it fails, you need to go deeper. These notes guide you through the ethical use of breach data and leak databases (like DeHashed and Snusbase) to find pivot points like old passwords or forgotten usernames.
It combines this with advanced image analysis using EXIF data extraction and Reverse Image Search engines (Yandex, PimEyes) to geolocate photos and identify people even from blurry crops. This section is critical for anyone needing to verify identities or track targets who are actively trying to hide.
Start Below
Don't rely on luck or expensive software. Equip yourself with the manual that teaches you to hunt like a state-sponsored actor.
Click Below to Buy the Full OSINT Notes Book Now
0 comments